11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

722 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresFirewall ConsiderationsCheck DescriptionLatest patches <strong>and</strong> updates are installed.Effective filters are in place to prevent malicious traffic from entering the perimeterUnused ports are blocked by default.Unused protocols are blocked by default.IPsec is configured for encrypted communication within the perimeter network.Intrusion detection is enabled at the firewall.Switch ConsiderationsCheck DescriptionLatest patches <strong>and</strong> updates are installed.Administrative interfaces are enumerated <strong>and</strong> secured.Unused administrative interfaces are disabled.Unused services are disabled.Available services are secured.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!